What actually grounds AI assurance?
We mapped 649 AI assurance controls across 332 published sources, from legislation and standards to incident reports and academic research. Along the way we realized something surprising: citation counts don't tell you which sources matter most.
Some references touch hundreds of controls without deeply grounding any of them. Others influence only a handful of controls, yet hold the only deep grounding those controls have in our corpus.
Measuring both breadth and depth reveals a very different picture of AI governance.
meta.method states every formula. A high depth score does not by itself make a source more authoritative: a narrow source can score high because it is mapped only where its fit is strongest. Of the 332 registered sources, 305 are cited by at least one control and are the ones scored here; the rest are registered references not yet mapped. One number in an earlier data cut counted mapping rows rather than distinct controls in two per-area subtotals; this version counts distinct controls throughout.| Measure | What it captures | What it does not establish |
|---|---|---|
| Breadth | Number of distinct controls a source maps | Importance or authority |
| Depth | Average directness of those mappings | The overall quality of a source |
| Uniqueness | How scarce alternative grounding is in this corpus | Absence from all published literature |
| Area rank | Average mapping depth within an area | How complete that area is |
Two kinds of value
The map below plots every substantial source. Breadth runs across: how many controls a source helps ground. Depth runs up: how directly it grounds them. Two broad roles emerge, though some sources fill both. A few broad frameworks stretch across the whole map; the EU AI Act, for one, is both the widest-reaching source and among the deeper ones. Far more numerous are the specialists, narrow but deep, each the strongest voice in its own lane. Filter by area to see who shows up where.
Broad frameworks connect many controls across areas, and often carry their own authority as law or standard. Within most individual areas, though, specialists provide the most direct grounding. The same split repeats when you look area by area.
The pattern repeats, area by area
Twelve areas of assurance, ordered by average grounding depth in our mappings, deepest first. Knowledge and resilience score highest. Security and model assurance draw on many sources, but their average mappings are among the least deep. The names beside each area are its three strongest mapped sources, ranked by fit-weighted mapping score.
Behind each of those leads sits a specialist doing what the broad frameworks cannot: giving one area its full depth. Without these sources, entire parts of the framework lose their deepest grounding.
Value also hides in narrow places.
Worth a lot, even when small
Some sources ground only a handful of controls, yet for certain controls they hold the only deep mapping in our corpus. No other source we have mapped goes as far on those controls. However small, these earn their place, because losing one leaves a control with no deep grounding at all.
These narrow sources answer a fair question about any large reference list: is the long tail padding? Here it is not. The tail is where several controls get their only deep grounding in the corpus. And measuring uniqueness this way exposed something larger than any single source.
One finding stood apart
Across eleven of the twelve assurance areas, the grounding in our corpus was merely uneven. In the agent-authority portion, one kind of grounding was absent: an end-to-end framework for agent-created organizational commitments, one that defines what an autonomous agent may commit an organization to, how that authority is delegated, where its limits end, and who ultimately remains accountable.
Because our own control structure shapes where a gap can appear, we treated this as a hypothesis rather than a verdict. We then searched deliberately, beyond the mapped corpus, for a framework that covered the full chain. The closest published attempt we found is a February 2026 IETF Internet-Draft on agent operation authorization: it specifies action-specific authorization, cryptographically bound user consent, and signed agent-to-agent delegation chains. It covers a real and important slice, but as a work-in-progress technical draft, not the organizational lifecycle, the aggregate commitment limits, the contracting obligations, the segregation of duties, and the board-level accountability that a commitment actually needs. Within the sources we mapped, and in that wider search, we found no published framework that governs the whole of it end to end.
Two limits worth naming. This analysis measures how much a source contributes to our control corpus; it does not yet score a source's external authority, its independence, or its currency, which is why a vendor guide and a binding law can sit near each other on the map. And sources enter the corpus through our ingestion process for the controls, not through a systematic literature search, so this is an analysis of the Apeiris collection, stated as such, not a survey of the whole field.
These results are calculated from Apeiris corpus version 2026.08.01, computed on 1 August 2026, covering 649 controls and 332 registered sources (305 cited by at least one control). Breadth, depth and uniqueness are computed consistently from the published source-to-control mappings; the mapping classifications themselves reflect documented analytical judgment and are open to review. Results describe this corpus and should not be read as a census of all published AI assurance literature. About 95 percent of framework citations are checked against source text available to us; separately, a blinded three-reviewer cross-model panel (OpenAI and Anthropic models) reviewed a 120-mapping stratified sample, agreeing at Krippendorff's alpha 0.779 (ordinal) with zero invalid citations (full results); the remainder cite proprietary sources whose text cannot be redistributed. The underlying data is open and CC BY 4.0.